Security & Privacy Statement
For client tenders, prequalification, and due diligence. Last updated: 7 May 2026.
At a glance
- Australian-operated advisory practice (Queensland)
- GST registered · Professional Indemnity insurance current
- Aligned with the Australian Privacy Act 1988 + Australian Privacy Principles
- Notifiable Data Breaches scheme: 30-day assessment + OAIC notification commitment
- Stripe-approved payment processor · PCI compliance handled by Stripe
- End-to-end TLS encryption in transit; provider-encrypted storage at rest
- Daily automated backups
- Audit log of every authentication, document export, and public-link access
Hosting and infrastructure
The DDES advisory platform is hosted on Railway (United States), a managed application platform with SOC 2 Type II controls. The application stack runs on isolated containers; the database lives on managed storage with automated daily backups retained for 7 days. Outbound transactional email is handled via Resend; payment processing is handled by Stripe (PCI DSS Level 1).
Access controls
- JWT bearer authentication with bcrypt-hashed passwords (10 rounds)
- Role-based access limited to DDES principals. No third-party staff access.
- Rate limiting on all public endpoints (10 req/min) and login (5 req/min)
- Public links (proposal acceptance, portal, payment) gated by single-use tokens with default 60-day expiry and admin revocation
- Standard HTTP security headers enforced: HSTS, X-Frame-Options, X-Content-Type-Options, Referrer-Policy, Permissions-Policy
Data handling
Client documents and engagement records are processed only for the purpose of delivering the engaged Services. We do not aggregate, mine, or sell client data. Data flows through the following subprocessors, each bound by their own contractual obligations:
- Railway (US) — application hosting + database
- Anthropic (US) — AI processing under commercial terms that prohibit training on client data
- Resend (US) — transactional email delivery
- Stripe (AU/US) — payment processing
- Google Cloud (US) — OAuth login (only where you opt in)
AI processing of your documents
Where you provide documents (existing SWMSes, SOPs, methodologies, scope material), we use AI tooling — currently Anthropic's Claude — to assist us in drafting, reviewing and auditing the deliverables we produce. Processing occurs under Anthropic's commercial API terms, which prohibit the use of your content for training their models. We do not authorise any AI subprocessor to retain your data beyond what is required to produce the response. Every AI-assisted output is reviewed by a DDES principal before delivery — we do not deliver raw AI output. If you have a contractual prohibition on AI processing, tell us before the engagement and we will arrange a manual workflow.
Audit and incident response
Every authentication event, document export, and public-link access is logged with a timestamp, IP address, and (where applicable) user agent. We retain this log for the duration of the engagement plus 7 years.
In the event of a notifiable data breach, we follow the Australian Notifiable Data Breaches scheme: assessment within 30 days, notification to the Office of the Australian Information Commissioner and to affected individuals where serious harm is likely. We will notify our clients directly within 72 hours of becoming aware of any breach affecting their data.
Data retention and your rights
- Active engagement records: retained for the duration of the engagement plus 7 years (PI insurance + tax obligations)
- Unprogressed enquiry data: retained for up to 24 months, then deleted
- Financial records: retained for 7 years (Australian tax law)
- You may request access, correction, or deletion of your information at any time, subject to our legal retention obligations
Security contact
For security inquiries, vulnerability disclosures, or to lodge a privacy complaint:
Email: scott@ddes.biz
Subject line: "SECURITY" for fastest triage
If unresolved, you may also lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au.